CenterPoint Energy Confirms Customer Data Theft From Internet-Facing System
CenterPoint Energy says an unauthorized party accessed customer personal information through an internet-facing company system. Energy delivery remains unaffected, but the utility has not yet disclosed the number...
Decade-Old Noodle RAT Resurfaces, Now Hunting Both Windows and Linux Systems Across Asia
Check Point researchers have tracked renewed activity from Noodle RAT, a cross-platform backdoor linked to Chinese-speaking threat actors and shared across multiple APT and cybercrime groups. Victims span...
For $250 a Month, Anyone Can Rent a Fully Featured Windows Spy Tool Called VectraRAT
Researchers have uncovered VectraRAT, a subscription-based remote access trojan renting for as little as $250 a month that gives buyers keylogging, hidden-desktop control, and credential theft on infected...
Japan Digital Agency Breach Exposes 246,000 Records After VPN Intrusion
Attackers exploited a previously patched VPN weakness to enter Japan’s shared government IT environment, potentially exposing about 246,000 personal records. The incident highlights the continuing danger of delayed...
Chrome 153 Patches 42 Security Flaws, Including Three Critical Memory Bugs
Google’s Chrome 153 stable update closes 42 vulnerabilities, including three critical memory-safety issues in Internals, Workers and WebGL. Users and administrators should ensure the browser has restarted on...
Apple’s Largest Coordinated Update Closes 273 Unique Vulnerabilities
Apple has issued coordinated updates across its device ecosystem addressing 273 unique CVEs. The fixes cover remote code execution, kernel privilege escalation, authentication bypass, privacy failures and web-content...
Luciferus Markets Subscription AI for Malware Development on Criminal Forums
A service called Luciferus is being promoted on an underground forum as an unrestricted AI assistant for malware-related requests. Researchers confirmed its willingness to generate RAT code, but...
Chinese Hacking Crew Weaponizes Critical Gitea Flaw to Hijack Self-Hosted Git Servers Worldwide
A Chinese-speaking intrusion set tracked as Red Heron is exploiting a critical remote-code-execution bug in self-hosted Gitea instances, deploying a custom Linux implant and rootkit against victims in...